nano-banana

Warn

Audited by Socket on Apr 13, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill's purpose and capabilities are mostly aligned for image generation/editing, and the Rebyte relay is disclosed rather than hidden. However, it requires an unverifiable local auth binary, reads a raw auth config file, and sends prompts plus optional source images through a third-party relay, so the overall footprint is higher risk than a normal direct API integration.

Confidence: 87%Severity: 78%
Audit Metadata
Analyzed At
Apr 13, 2026, 02:01 PM
Package URL
pkg:socket/skills-sh/rebyteai%2Frebyte-skills%2Fnano-banana%2F@9e98913c8e042a42bc6231740cf0475442cac920